4 ms·
The hackers got access to their dev environment and source code back in August and used that information to hit them harder this time around: https://blog.lastp
by DisjointedHunt 4y ago
The hackers got access to their dev environment and source code back in August and used that information to hit them harder this time around: https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/ https://blog.lastpass.com/2022/12/notice-of-recent-security-...
We may not be seeing the whole picture yet, but very concerning that the dev environment had access to Production database backups stored in a manner that was easily decrypt-able :/ The whole point of a Dev environment in a security focused company is that you reduce the surface area for access and failure.
- raffraffraff 4y agoWooo. > dev environment had access to Production database backups stored in a manner that was easily decrypt-able Say what you like about old dinosaur companies like banks, but when I worked in the IT department for a bank back in the early 2000s developers absolutely couldn't touch production systems, data or backups. Ever. They always has to go through ops even during major incidents. Of course banks aren't immune to fuckups, but at least on paper they tend to have sound security policies. Startups are great at moving fast because there are no guardrails. Like lemmings, corps, banks and government entities externalize their risk to the third party because they recognize the name and logo. "Should we go with SecureCompany(tm)?". "Yeah, everybody uses them". It's great for startups. Without red tape and heavy policy your lean team can create products that the hamstrung bigcorp could only dream of (just don't look under the UI!). They slowly build their customer base, and when they're ready to IPO, they run through some security and process certification theatre, and the investors and a handful of executives can make billions. Overall, both sides seem to be happy with the situation. Bigcorp gets to cut tech staff and outsource, and they have a convenient finger to point when the regulator asks questions. The SaaS apologises and maybe loses a customer or two, but based on stock prices after major issues like this in the past, nothing bad really happens.
- cj 4y agoRe: dev environment containing database backups, here’s the full text on that point from the blog: > some source code and technical information were stolen from our development environment and used to target another employee, obtaining credentials and keys which were used to access and decrypt some storage volumes within the cloud-based storage service. It sounds like they didn’t literally have backups in the dev environment (which would be absolutely terrible if they did). I’m guessing they learned enough about the architecture from the dev environment to social engineer their way into getting someone to give them credentials to production.